IP Library Granted Patent US 12694140
Granted Patent B2
US 12694140 · App. 18/913,346 · Granted Jul 28, 2026

System and method for software service policy exception in computing environments

Inventors: Or Tzabary (Tel Aviv, IL); Ami Luttwak (Binyamina, IL)
Assignee: Wiz, Inc.
G06F21/6209G06F11/3668G06F21/577H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694140
App. No.
18/913,346
Granted
Jul 28, 2026
Kind
B2
Abstract

A system and method for managing a cybersecurity policy exception on a software service in a computing environment is presented. The method includes detecting a software service in a computing environment, the service including a code object and a resource; generating a representation of the software service in a security database, the security database further including a representation of the computing environment; applying a policy on the representation of the software service, the policy including a conditional rule; detecting a policy exception in response to applying the policy resulting in a policy fail of the conditional rule; determining that the software service passes the policy in response to applying the policy exception resulting in a pass; and initiating a remediation action, in response to determining that applying the policy exception results in a policy fail.

Claims (57)

1 . A method for managing a cybersecurity policy exception on a software service in a computing environment, comprising:

detecting the software service in the computing environment, the software service including a code object and a resource;

generating a representation of the software service in a security database as a portion of a security graph, wherein the representation of the software service is connected to a representation of the code object and a representation of the resource, wherein the representation of the code object, the representation of the software service, and the representation of the resource are nodes of the security graph, and wherein the security database further including a representation of the computing environment in the security graph;

applying a policy on the representation of the software service, the policy including a conditional rule;

detecting a policy exception in response to applying the policy resulting in a policy fail of the conditional rule;

determining that the software service passes the policy in response to applying the policy exception resulting in a pass; and

initiating a remediation action, in response to determining that applying the policy exception results in a policy fail.

2 . The method of claim 1 , further comprising:

applying the policy exception only in response to determining that the applied policy on the representation of the software service results in a fail of the conditional rule.

3 . The method of claim 1 , further comprising:

generating the policy exception in response to applying the policy resulting in a policy fail of the conditional rule.

4 . The method of claim 1 , further comprising:

applying the policy exception to each representation of a component of the software service.

5 . The method of claim 4 , further comprising:

determining that the software service fails the policy, in response to determining that a representation of a first component of the software service passes the policy exception, and a representation of a second component of the software service fails the policy exception.

6 . The method of claim 5 , further comprising:

initiating the remediation action on the second component of the software service.

7 . The method of claim 1 , further comprising:

initiating the remediation action on each component of the software service.

8 . The method of claim 1 , further comprising:

applying the policy exception on each component of the software service.

9 . The method of claim 1 , further comprising:

applying the policy exception on each of a plurality of software services, in response to determining that the plurality of software services are similar to the software service.

10 . A non-transitory computer-readable medium storing a set of instructions for managing a cybersecurity policy exception on a software service in a computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

detect the software service in the computing environment, the software service including a code object and a resource;

generate a representation of the software service in a security database as a portion of a security graph, wherein the representation of the software service is connected to a representation of the code object and a representation of the resource, wherein the representation of the code object, the representation of the software service, and the representation of the resource are nodes of the security graph, and wherein the security database further including a representation of the computing environment in the security graph;

apply a policy on the representation of the software service, the policy including a conditional rule;

detect a policy exception in response to applying the policy resulting in a policy fail of the conditional rule;

determine that the software service passes the policy in response to applying the policy exception resulting in a pass; and

initiate a remediation action, in response to determining that applying the policy exception results in a policy fail.

11 . A system for managing a cybersecurity policy exception on a software service in a computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect the software service in the computing environment, the software service including a code object and a resource;

generate a representation of the software service in a security database as a portion of a security graph, wherein the representation of the software service is connected to a representation of the code object and a representation of the resource, wherein the representation of the code object, the representation of the software service, and the representation of the resource are nodes of the security graph, and wherein the security database further including a representation of the computing environment in the security graph;

apply a policy on the representation of the software service, the policy including a conditional rule;

detect a policy exception in response to applying the policy resulting in a policy fail of the conditional rule;

determine that the software service passes the policy in response to applying the policy exception resulting in a pass; and

initiate a remediation action, in response to determining that applying the policy exception results in a policy fail.

12 . The system of claim 11 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

apply the policy exception only in response to determining that the applied policy on the representation of the software service results in a fail of the conditional rule.

13 . The system of claim 11 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

generate the policy exception in response to applying the policy resulting in a policy fail of the conditional rule.

14 . The system of claim 11 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

apply the policy exception to each representation of a component of the software service.

15 . The system of claim 14 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

one or more processors are further configured to:

determine that the software service fails the policy, in response to determining that a representation of a first component of the software service passes the policy exception, and a representation of a second component of the software service fails the policy exception.

16 . The system of claim 15 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system:

initiate the remediation action on the second component of the software service.

17 . The system of claim 11 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

initiate the remediation action on each component of the software service.

18 . The system of claim 11 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

apply the policy exception on each component of the software service.

19 . The system of claim 11 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

apply the policy exception on each of a plurality of software services, in response to determining that the plurality of software services are similar to the software service.